
Advertise on podcast: Cyber Voices
This podcast has
88 episodes
Language
EnglishExplicit
No
Date created
2024/10/17
Latest episode
2026/09/30
Average duration
33 min.
Release period
7 days
Description
Welcome to CYBER VOICES, where we highlight and celebrate the diverse voices of the Australian cyber community. From top-ranking CISOs and government officials to threat hunters and vulnerability analysts, if there’s a voice to be heard, you’ll hear it on CYBER VOICES. Join us as we delve into the stories, insights, and expertise that shape the world of cybersecurity in Australia.
Unlock Cyber Voices podcast Email contact info,
Listeners & Audience details
Email contact information
Direct podcast contact details

Listeners
Audience numbers & engagement insights

Audience details
Podcast Insights

Podcast episodes
Check latest episodes from Cyber Voices podcast
Your Company Through the Eyes of an Info Stealer, with Jesse Hoppo
2026/09/30
Information stealing malware is not new and not sophisticated. That is precisely what worries Jesse Hoppo, who leads the open source intelligence and cyber crime team within Telstra's Threat Research and Intelligence Group, and who spends a good deal of his time reading what these things send home.
Recorded at AdelaideSEC, Jesse joins David Savva-Willett after his talk on what an organisation looks like through an info stealer's eyes. He explains how the malware arrives, usually by persuading someone to run a command themselves rather than through any exploit, and what a single log actually holds: browser credentials, session cookies, clipboard contents, search history, a screenshot of the desktop, whatever documents looked interesting.
His central reframe is that the useful question is not what an attacker can do with a stolen password, but what they can do as that person. He also describes the browser password sync problem that quietly carries corporate credentials onto home machines, the exposure a single employee device can create, and the hardest question he has tried to answer for a large organisation: where are all the places your people can log in and access data?
The conversation closes on what actually helps, for organisations and for individuals, including why he would rather you used any dedicated password manager than the one built into your browser.
Agentic GRC and the Limits of AI, with Ian Yip and Jack Hedges
2026/09/24
Governance, risk and compliance generates a great deal of manual work, and not all of it is work anyone would miss. Ian Yip's argument is that this is exactly where AI earns its place in a security team, provided nobody mistakes it for judgment.
Ian is the founder and CEO of Avertro, the company behind the cyber and AI governance platform CyberHQ, and he recently delivered a standing room only session on agentic GRC at Infosecurity Europe in London. He joins David Savva-Willett along with Jack Hedges, a strategic account executive at Avertro who works with security leaders across Australia.
Ian sets out a way of thinking rather than a technology: build an agentic team the way you would build a human one, as an org chart of narrow specialists that collaborate, because models do their best work when given one task rather than many. Chained together and scheduled, that team absorbs the evidence collection, the framework crosswalks and the board reporting, leaving the humans the work they would rather be doing.
What cannot be delegated is taste, which Ian describes as the ability to look at what a model hands back and know what to strip away. The conversation covers how much of GRC is theatre and which of that is still necessary for auditability, why he believes everyone is now a builder, what European regulators do differently and why their real effect is on budgets rather than behaviour, and Jack's view from the field, where a lack of visibility over what staff are already using has overtaken cyber GRC as the pressing concern.
Are ChatGPT, Claude or Gemini Useful in a Breach Investigation? with Josh Lemon
2026/09/16
Threat actors are already using large language models to accelerate the early stages of a compromise. Josh Lemon wanted to know what the same tools could do for the responders on the other side.
Recorded at AdelaideSEC 2026, David Savva-Willett speaks with Josh Lemon, Chief of Digital Forensics and Incident Response at SoteriaSec and a SANS principal instructor, immediately after his talk on that question. Josh has been putting the major models in front of forensic evidence for years, and reports real movement: where they once sent an inexperienced analyst off in entirely the wrong direction, they now answer factual questions reliably. What they still lack is the creativity to ask why something is wrong, or what a threat actor is likely to do next.
The discussion ranges across where LLMs are genuinely saving hours in a SOC, from one off Python tooling to threat intelligence summaries to executive status updates; a response Josh received that read unmistakably like vendor advertising; why he warns his students that an AI written report may one day be read by an expert witness in court; how MCP servers are being folded into SANS forensics classes; and whether any of this helps with the on call burden and burnout that have dogged the profession for years.
It closes on the exchange every responder knows by heart, where no evidence of exfiltration gets heard as no exfiltration, and Josh's observation about what a model eager to please would say if a lawyer asked it the same question.
AI Agents as Workers, with Sharon Hunneybell
2026/09/09
Most organisations still treat AI agents as software. Their staff do not. Agents are being used as colleagues, confidants and co-developers; they are being handed access to multiple systems, and a good number of them belong to proof-of-concept projects that quietly ended without anyone shutting off the credentials.
Recorded at AdelaideSEC, David Savva-Willett speaks with Sharon Hunneybell, VP of Products at FirstWave, ahead of her talk on a governance framework for AI agents as workers. Sharon describes realising midway through writing that framework that she had missed a step, and that discovery has to come before onboarding, because these things arrive in the workplace unannounced and increasingly as features inside software that is already approved.
The conversation covers where accountability sits when an agent acts, why access should be task-based and time-limited rather than granted to one broad agent, how far traditional HR frameworks actually translate, and what Sharon expects from regulation over the coming months. It closes on her practical checklist: give every agent its own identity, log what it does, scope its access to a single task, review it on a schedule, and know how to offboard it before you build it.
Post-Quantum Cryptography and Passkeys, with Geoff Schomburgk and Alex Wilson (Yubico)
2026/09/02
Quantum computers will one day break the cryptography that protects almost everything online. The harder questions are how much of the alarm is warranted, and what security leaders should be doing now.
David Savva-Willett is joined by Geoff Schomburgk, Regional Vice President for Asia Pacific and Japan at Yubico, and Alex Wilson, who leads solutions engineering for the region. They unpack harvest now, decrypt later and how much of it is a device for grabbing attention; what it took to get post-quantum algorithms running on the secure element inside a YubiKey; and why crypto agility, not any single algorithm, is the thing to design for.
The conversation turns to authentication, where passkeys are becoming the root of trust for digital wallets, mobile driver licences and financial transactions, and to the difference between device bound and copyable passkeys that many organisations have not thought through. Both guests make the case that this is a project management and governance problem rather than a technology one, and that the apocalyptic framing does more harm than good.
Everyone Has a Unique Talent: Christine Ferguson on Neurodiversity in Cyber
2026/08/26
Recorded live at AISA SydneySec 2026, host David Savva-Willett is joined by Christine Ferguson, Inclusion Specialist Lead in DXC Technology's Social Impact Practice, where she leads the DXC Dandelion Program. Since 2014 the program has supported over 350 neurodivergent people into sustainable technology and cyber security careers across Australia, Europe, Asia and now the Middle East.
Christine had just come off stage with her SydneySec session Neurodiversity in Cyber: People, Pressure and Performance, and the conversation follows the same three threads. What neurodivergent professionals bring to a cyber team that routinely gets overlooked. What pressure and masking actually feel like from the inside, and why an escalating manager and an escalating analyst never produce a good outcome. And what genuinely changes for a team, not just an individual, when a workplace gets the accommodations right.
Christine speaks openly about her own dyslexia and about wearing the Hidden Disabilities Sunflower lanyard at the conference so that people could see an invisible disability made visible. She closes with the one small change she would ask of any leader listening, which turns out to cost nothing at all.
Cyber Voices is the official podcast of the Australian Information Security Association. Share your feedback at [email protected].
The Only Criminologist in the Room: Nakshathra Suresh on Human Centred Resilience
2026/08/19
Recorded live at AISA SydneySec 2026, host David Savva-Willett sits down with Nakshathra Suresh, a cyber criminologist and one of very few people in Australia bringing a social science lens to artificial intelligence and emerging technology safety.
Nakshathra is co-founder of eiris, a safety technology consultancy, Oceania Youth Ambassador for the Internet Society, and teaches with the Faculty of Law and Justice at UNSW where she created the university's first criminology backed cyber security course.
The conversation covers what a cyber criminologist actually does and why the discipline is still so young, how generative AI has turned catfishing and cyberstalking into something that runs itself once a public profile is scraped, the long tail of harm for victim survivors who end up retiring their online lives entirely, and why human centred resilience is a question of culture and conduct rather than another vulnerability to patch. Nakshathra also makes a direct case about who is missing from the room when security decisions get made.
Content note: this episode includes discussion of cyberstalking, technology facilitated abuse, image based abuse and harm to children in online environments. If anything here raises something for you, support is available. 1800RESPECT on 1800 737 732 or Lifeline on 13 11 14, and image based abuse can be reported to the eSafety Commissioner at esafety.gov.au.
Cyber Voices is the official podcast of the Australian Information Security Association. Share your feedback at [email protected].
Fighting Back: Glenn Maiden on Putting a Bounty on Cybercrime
2026/08/12
Cybercrime is not a lone hacker in a hoodie any more. It is an economy, and by some estimates a staggeringly large one. In this episode of Cyber Voices, host David Savva-Willett flips the usual script and asks not how we defend, but how we fight back.
Glenn Maiden is Chief Security Officer for Fortinet Australia and Director of Threat Intelligence at FortiGuard Labs for Australia and New Zealand. He spent years in Defence and the Australian Intelligence Community working in geospatial and human terrain intelligence, including during Operation Slipper, before moving into commercial threat intelligence. He established the team behind the World Economic Forum's Cybercrime Atlas and, most recently, helped create a first of its kind cybercrime bounty program with Crime Stoppers International.
The conversation covers how mapping tribal structures, community leaders and wells in a conflict zone translates to mapping the humans behind ransomware crews, why our industry has become excellent at indicators of compromise and knows almost nothing about the actual people, and what the Cybercrime Atlas found when it started pulling names, aliases, bank accounts, crypto wallets and bulletproof hosting together into targeting packages for Interpol, Europol and the FBI.
David and Glenn also dig into why better defence alone was never going to be enough, the gap that sits on the people and process side rather than the technology side, and the unreported soft underbelly of an economy built on small and medium business. Glenn explains how the new bounty program works, how someone with intelligence on a threat actor can submit an anonymous tip and potentially collect a reward when that person is arrested and prosecuted, and why the same infrastructure mapping may help pull far worse criminals off the streets.
There is a human side too. Glenn talks about the young man in Eastern Europe committing cybercrime to get his family out, the scam compounds operating a couple of hours to Australia's north, and his own experience of being scammed through Facebook Marketplace. He explains why he tells that story publicly and how shame keeps victims silent.
Glenn closes with practical advice for CISOs, SOC leads and analysts who will never run a takedown themselves.
Content note: this episode includes brief references to human trafficking, forced labour in scam centres and child exploitation material in the context of organised crime.
Cyber Voices is the official podcast of the Australian Information Security Association. Share your feedback at [email protected].
The Ones Who Do Nothing: Ant Cohen on What Your Phishing Metrics Are Missing
2026/08/05
On this episode of Cyber Voices, host David Savva-Willett is at the tail end of Canberra CyberConnect 2026, AISA's first ever event in the nation's capital, sitting down with a guest who has one of the best job titles in Australian cyber.
Ant Cohen is Head of Security Influence and Trust at nbn. Before cyber, he built some of the most recognisable marketing campaigns this country has seen, from Oprah's Australian adventure to 25 Wallabies campervans touring New Zealand during the Rugby World Cup to a gold medal winning campaign for the Australian Olympic and Paralympic teams in London. He now brings that storytelling firepower to human centred cyber defence, and sits on a NSW Crime Stoppers advisory committee.
David and Ant get into why security awareness has a well earned reputation for being boring and occasionally condescending, and Ant's diagnosis of the problem: an oversupply of supply. The industry has indulged in training, drills and metrics reporting without ever building the demand.
The idea that stops David in his tracks is the do nothing cohort. Security teams obsess over the people who click and celebrate the people who report, but the largest group by far is the people who open the simulation, leave it sitting in the inbox and take no action at all. Ant explains why the time of day, the device and the out of office setting tell you far more about your culture than a click rate ever will, and why he is a believer in small data over big data.
The conversation also covers whether phishing simulations remain tenable after a decade of use, the difference between decisions made cold and decisions made in the heat of the moment, closing the loop so people know a human actually reads what they report, and the scale of nbn's responsibility given the proportion of Australia's daily data traffic that crosses the network. Ant's team of four works alongside nbn Local to reach regional and rural communities, libraries and the Country Women's Association with scams education aimed squarely at the Australians most often targeted.
And his one thing for cyber leaders heading back to work on Monday: learn your audience, and learn the language they actually speak.
Recorded live at Canberra CyberConnect 2026.
The Human Firewall: Darren Fleming on Staying Clear Headed in a Crisis
2026/07/29
Every playbook and SOP you have ever written assumes it will be picked up by a calm, fully regulated human. My guest this episode reckons that assumption is exactly where incident response quietly falls apart.
Recorded live at AISA's inaugural CyberConnect Canberra 2026 at the Hotel Realm, David Savva-Willett sat down with Darren Fleming, peak performance strategist, author, and the man better known as That Mindfulness Bloke. Darren represented Australia in elite sailing, studied psychology and philosophy at Oxford, has written seven books on communication, leadership and mindset, sat in complete silence for ten days, and spent more than twenty years coaching global organisations including Caterpillar, Cisco, BHP and Rio Tinto on how to perform under pressure.
His CyberConnect talk, The Human Firewall, covers the thing no runbook touches: what actually happens to a responder's brain in the first hours of a Sev1.
They get into why the nervous system, not the playbook, makes the decision. How adrenaline and cortisol cut off access to long term memory, and why "it made sense at the time" is a physiological answer rather than an excuse. The difference between situational awareness, stretched awareness and tunnel vision, and why "I just didn't see it" keeps turning up in the debrief. Why incident teams start turning on each other under pressure, and why that is the body working exactly as designed rather than a culture problem. What ten days of Vipassana taught Darren that a psychology degree could not. The collapse of the average attention span from roughly two and a half minutes to under a minute in twenty years. How a SANFL club lifted its win rate by changing what three senior players did during the half time break. And the one technique Darren would hand a CISO heading into a tabletop next week.
Find out more about Darren's work at thatmindfulnessbloke.com
Cyber Voices is the official podcast of the Australian Information Security Association. Subscribe wherever you get your podcasts and leave us a five star rating, it genuinely helps others find the show. Learn more about AISA or become a member at aisa.org.au
Earning the Chair: How Graham Fairley Became PEXA's CISO
2026/07/22
Most people arrive at the CISO chair from the outside. Graham Fairley did the opposite — he earned it from within.
In this episode, host David Savva-Willett sits down with Graham Fairley, Chief Information Security Officer at PEXA (Property Exchange Australia), for a candid and personal conversation. Davey held the CISO role at PEXA before Graham, and the two have been friends and colleagues for the better part of a decade — which makes this a rare, honest look at what it actually takes to grow into one of the most demanding seats in Australian cyber.
Graham progressed through identity and access management, security consulting and a security services lead role before stepping into the CISO chair in late 2024. Eighteen months in, he reflects on the learning curves nobody warns you about: winning executive and board buy-in, sitting with the weight of accountability, learning to let go of the technical work he loves, and becoming the kind of storyteller a modern security leader has to be.
They also get into what PEXA actually protects — a platform underpinning Australia's ~$10 trillion property market and designated critical infrastructure — including the 6.5 million intrusion attempts PEXA blocked in a single financial year, four times the previous year's volume. Graham unpacks PEXA's layered defence approach, and the harder problem beyond the platform: the consumer. As he puts it, criminals don't need to compromise systems — they just need to compromise trust. In this episode:
Why the "internal" route to CISO is undervalued — and the edge it gives youThe first 18 months in the chair, and the skills that sharpened fastestWhy every CISO has to be a storyteller (and where AI genuinely helps)Learning to step back so the team — not the CISO — becomes the heroDefending critical infrastructure at scale: layered controls, threat intel and speed-to-detectSocial licence, shared accountability and PEXA's Safeguarding Your Property Settlement white paperAI-supercharged business email compromise, and the "stop and think" habits that stop itReal advice for anyone who wants the CISO job one dayCyber Voices is the official podcast of the Australian Information Security Association (AISA). If you're enjoying the show, a five-star rating (about five seconds of your time) genuinely helps more people find it.
Interested in sponsoring Cyber Voices or reaching the AISA community at CyberCon? Contact the AISA national events and sponsorship team via [email protected].
#CyberSecurity #CISO #AISA #CyberVoices #PEXA #CriticalInfrastructure #InfoSec #Leadership
Breachonomics Redux: Grant McKechnie on the Untold Cost of a Data Breach
2026/07/15
On this episode of Cyber Voices, host David Savva-Willett is on the ground at Canberra CyberConnect 2026, AISA's inaugural event in the nation's capital, sitting down with Grant McKechnie for a conversation that CFOs and board members need to hear.
Grant is Managing Partner at Cyber Resilience Group and a two-decade CISO veteran of Endeavour Group, Telstra and NBN. He was named one of the top 10 CISOs in Asia Pacific in 2022 and has built greenfield cyber security functions across some of Australia's most critical infrastructure. Today at CyberConnect he has returned with Breachonomics Redux, a follow up to the passion project he has been researching for the past four years on the untold economic and human impacts of a data breach.
We get into the share price data behind major Australian and global breaches, from Medibank's 198 days back to parity to Live Nation's share price actually climbing after a breach affecting 560 million records. Grant unpacks why the market is becoming ambivalent, why Australian penalties never match the crime, and why trust and communications have overtaken share price as the impact he now leads with when advising boards. We also dig into how threat actors are adapting (including calling the regulators on their own victims), why information sharing has quietly gotten worse even as we appear to share more, the three critical first hires when building a cyber function from a blank page, the underrated art of finding a board sponsor before you need one, and the crucial difference between what belongs in an ARC pack versus a full board pack.
If you have a CFO or a board member in your life, this is the one to forward on
Rain, Hail or Shine: Chris Stannage on Cyber Run Club, Community and Mental Health
2026/07/08
This episode is a little bit different. Yes, my guest works in cyber security, but we are not here to talk about breach containment or zero trust architecture. We are here to talk about the people behind the industry and what it actually takes to show up and do this job sustainably.
Chris Stannage is a Scottish born, Melbourne based Senior Account Executive at Illumio, a former competitive rugby player, and the founder of Cyber Run Club, a monthly gathering at the Tan that brings cyber professionals together for movement, fresh air and honest conversation with zero pressure and zero sales pitches.
We chat about the lunch that sparked the whole idea, the strictly sales free ethos and why it works, the organic connections made along the way (including an analyst picking the brain of a CISO mid jog), mental health in our industry and why talking early matters, what competitive rugby taught Chris about teams and discipline, and his unlikely path from a microbiology degree to cyber sales.
Cyber Run Club meets on the last Thursday of every month at the Tan in Melbourne. Walk, jog or run, everyone is welcome, from students to CISOs. Find the group by searching Cyber Run Club on LinkedIn.
A note on mental health: our conversation is general in nature and we are not experts in this space. If anything in this episode raised something for you, support is available. Lifeline 13 11 14 or lifeline.org.au. Beyond Blue 1300 22 4636 or beyondblue.org.au.
Emily Holyoake on Security Culture, Human Risk and Canberra Roundabouts
2026/07/01
Recorded live at the inaugural Canberra CyberConnect 2026, David sits down with Emily Holyoake, Executive Director and co-founder of Not A Standard and one of the creators of the SAFE Framework, a multidisciplinary approach that brings cyber security, criminology and behavioural science together to map how adversaries exploit people, technology and systems. Emily is a proud Wurundjeri woman and a passionate advocate for neurodiversity in cyber.
In this conversation, Emily unpacks the thinking behind one of the best titled talks on the program, Navigating Human Risk: What to Do When Your Security Culture Handles Like a Canberra Roundabout. She explains why great security culture is really a design problem, when you want people safely on autopilot and when you want them to slow down and think, and why phishing simulations so often do more harm than good. Along the way she makes the case that humans are our greatest asset rather than the weakest link, that looking after our people is the best defence against insider risk, and that we all need to be wrong more.
Whether you are a new CISO building your first 30-day plan or you simply want to bring your security program back to the people it serves, this one is full of practical and genuinely human thinking.
Please note this episode contains a brief reference to suicide. If anything in this episode affects you, support is available in Australia through Lifeline on 13 11 14 or at lifeline.org.au. If this conversation resonates with you, subscribe to Cyber Voices on your podcast app of choice and leave us a five-star review. It helps others find the show.
Cyber Voices is the official podcast of the Australian Information Security Association (AISA).
The Sword Cuts Both Ways: Professor Toby Walsh on AI, Mythos and the New Normal in Cyber
2026/06/24
On this episode of Cyber Voices, host David Savva-Willett is at Canberra CyberConnect 2026, AISA's inaugural event in the nation's capital, for a wide-ranging conversation with Professor Toby Walsh, one of the world's most influential voices in artificial intelligence.
Toby is a Professor of AI at UNSW Sydney and Chief Scientist of UNSW AI. He has advised the United Nations and heads of state on the limits we need to place on AI, and his outspoken stance on the military uses of the technology famously earned him an indefinite ban from Russia.
In this conversation, Toby and David dig into what AI really means for cyber defenders right now. They discuss Anthropic's Mythos and the wave of decades-old zero-day vulnerabilities now being uncovered, why this is the new normal rather than a one-off event, and how AI has democratised offensive capability so that sophisticated attacks no longer require deep technical expertise.
They also explore the questions that matter most for security leaders: whether defenders are really losing the AI arms race, why dwell time has collapsed from 200 days to a smash-and-grab measured in hours, the rise of shadow AI arriving both top down and bottom up, the sovereignty risk when powerful tools are released only to a select few, and the lessons from the Canvas breach where attackers did not hack the front door, they simply logged in.
Toby also lifts the lid on the ideas behind his latest book, The Shortest History of AI: Six Ideas Are All You Need to Know, including why AI is a 70-year overnight success and why the human brain, running on the power of a dim light bulb, still puts our most advanced machines to shame.
Whether you are a CISO being asked to govern AI while still learning it yourself, or simply trying to separate the signal from the hype, this is a clear-eyed and occasionally very funny look at where AI and cyber security collide.
Topics covered:
Why AI is a double-edged sword for cyber, threat and defence at onceAnthropic's Mythos and the discovery of zero-day flaws nearly 30 years oldHow AI has lowered the barrier to entry for sophisticated attacksWhether defenders are losing the AI arms raceDwell time collapsing from 200 days to under two hoursShadow AI, and how security leaders can actually govern itSovereignty risk and the case for stronger regulationThe Canvas breach and the era of just logging inSix big ideas from The Shortest History of AI
Cyber Voices is the official podcast of the Australian Information Security Association (AISA).
Podcast reviews
Read Cyber Voices podcast reviews
Podcast sponsorship advertising
Start advertising on Cyber Voices relevant audience podcasts
You may also like to advertise on these Podcasts

51088171
Middle Children
Jessie Jolles and Chris Burns

4.9264932000
Morning Wire
The Daily Wire

4.518760369
American Scandal
Audible

4.689261200
Get Sleepy: Sleep meditation and stories
Slumber Studios

4.79026375
Life is Short with Justin Long
Audible

4.714083346
Bad Friends
Bobby Lee & Andrew Santino

4.7124668
10 to Life
Annie Elise

4.76746460
Criminology
Emash Digital & Mike Ferguson, Mike Morford

4.87488968
The Dr. John Delony Show
Ramsey Network

4.512539657
RedHanded
RedHanded